Manager, Compliance and Critical Infrastructure Protection
Listed on 2026-08-27
-
Security
Cybersecurity
Summary Job Description Essential Functions
- Oversee corporate NERC and CIP compliance structures, processes, and program governance.
- Establish and maintain policies, procedures, and internal controls for effectiveness and alignment with regulatory requirements.
- Evaluate CIP cybersecurity and physical security programs and advise on enhancements to ensure alignment with regulatory requirements.
- Oversee compliance with Railbelt Reliability Council CIP and Reliability Standards and other applicable NERC and FERC requirements.
- Lead and manage audits, spot checks, and investigations.
- Oversee organizational readiness for audits, spot checks on existing procedures and policy, and investigations, and coordinate responses to regulatory inquiries.
- Review and evaluate regulatory documentation and evidence prepared by operational teams to ensure completeness and accuracy.
- Direct risk assessments and mitigation activities for BES Cyber Systems and advise on mitigation strategies to ensure alignment with CIP requirements.
- Monitor emerging threats and regulatory developments.
- Review cybersecurity and physical security incident response plans for compliance with applicable regulatory requirements.
- Assess alignment of OT and IT controls with applicable compliance standards and report findings to leadership.
- Advise operational technical teams on incorporating compliance and CIP requirements into operational planning and system lifecycle processes.
- Liaise with regulatory bodies and industry groups.
- Participate in Railbelt Reliability Council Standards development work groups.
- Oversee development and delivery of CIP and Reliability Standards compliance training programs.
- Prepare and deliver reports to leadership and the Board of Directors.
- Lead internal self-assessments and mock audits.
- Oversee and evaluate compliance documentation systems and tracking tools for consistency and quality.
- Other duties as assigned.
- Chief Legal Officer:
Report to, receive direction, guidance and decisions from. - Board of Directors:
Give and receive information. - Division Managers and Leadership:
Confer with, give and receive information. - Other Managers and Staff:
Confer with, give and receive information.
- Bargaining Unit Representatives
- Regulators, State and Federal Agencies:
Coordinate with, give and receive information. - Other Utilities:
Coordinate with, give and receive information.
- Advanced knowledge of NERC Reliability and CIP Standards, FERC regulations, and regional requirements.
- Knowledge of cybersecurity principles, SCADA/ICS environments, and BES Cyber Systems.
- Proficiency with compliance tracking tools and documentation systems.
- Ability to identify sensitive or confidential information and abide by confidentiality requirements.
- Ability to perform in a fast paced and deadline-oriented environment.
- Ability to organize workflow, manage multiple priorities, and effectively utilize resources.
- Ability to apply tactical applications and decision making to long-term and strategic objectives.
- Effective verbal, written, and negotiation skills with the capability to clearly convey both technical and strategic information to various audiences.
- Proven ability to uphold ethical and professional conduct.
- Advanced knowledge of Microsoft Office applications.
This position does not have direct supervisory responsibility.
Work EnvironmentWork is performed in a standard office environment. Some evening and weekend work may be required occasionally. Occasional air travel is required. Attendance at Board of Directors’ meetings and conferences outside of the state may be required.
Minimum Qualifications And Experience EducationBachelor’s degree in Engineering, Information Technology, Cybersecurity, Business or related field, required. Master’s degree, preferred.
ExperienceFive (5) years of progressively responsible experience, including working in a lead or primary role in compliance, cybersecurity, operations, or risk management, required. Experience managing NERC Reliability Standards, NERC CIP programs, or RRC CIP cybersecurity standards, preferred. Experience leading audits, investigations, and assessments,…
(If this job is in fact in your jurisdiction, then you may be using a Proxy or VPN to access this site, and to progress further, you should change your connectivity to another mobile device or PC).